CVE-2026-75604: Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.
References
- github.com/advisories/GHSA-p293-qw3h-jr36
- github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b
- github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3
- github.com/vercel/next.js/releases/tag/v15.5.24
- github.com/vercel/next.js/releases/tag/v16.3.3
- github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
- nvd.nist.gov/vuln/detail/CVE-2026-75604
Code Behaviors & Features
Detect and mitigate CVE-2026-75604 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →